Handout Cloud Security Fundamentals On AWS
Handout Cloud Security Fundamentals On AWS
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Security fundamentals in AWS
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Session agenda
Cloud myths and misconceptions
Security capabilities
Call to action
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Cloud myths and misconceptions
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Cloud myths and misconceptions
I have digital sovereignty requirements…
Can AWS access my data?
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Build, migrate and
modernize securely
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Build, migrate and modernize securely
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Proven security to accelerate innovation
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
The most secure infrastructure
Challenge
Build on a cloud that provides the security and
confidence to accelerate innovation
AWS approach
• 143 security and compliance certifications
• Secure-by-design
• Most operational experience
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Security automation that drives speed and
agility
Challenge
Automate security checks to continually enforce
controls and mathematically prove the highest
levels of security
AWS approach
• Provable security
• Automatically detect security events
• Security automation at scale
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
End-to-end security and guidance
Challenge
Implement every step of your organization’s
optimal security posture
AWS approach
• 300+ security services and features
• Thousands of security solutions on AWS
Marketplace
• Open source security
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Shared Responsibility Model
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Shared Responsibility Model
Customer responsibility is
Security ‘IN’
determined by the AWS Cloud
the cloud services they select.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Security capabilities
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS security, identity, and compliance
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Identity and access management
Securely manage and govern access for your customers, workforce, and workloads
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Identity and access management
Securely manage and govern access for your customers, workforce, and workloads
AWS Cloud
AWS Organizations
Amazon Cognito AWS Identity and Access AWS IAM Identity Center
Management (AWS IAM)
Workforce
External users
users
Authenticated
user
Public app Logs
Workforce Workforce
app 1 app 2
Permissions Permissions Permissions
Amazon Verified Permissions
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Detection and response
Continuously detect and respond to security risks to help protect your workloads at scale
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Detection and response
Continuously detect and respond to security risks to help protect your workloads at scale
AWS Cloud
AWS Organizations
VPC
Users
Logs
Amazon GuardDuty
Security
team
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Network and application protection
Enforce fine-grained security policy at every network control point
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Network and application protection
Enforce fine-grained security policy at every network control point
AWS Cloud
AWS Organizations
VPC
Users
Amazon
Public subnet Private subnet
Route 53
Security group Security group
Amazon
CloudFront
Application Database
AWS Shield
Malicious
client
AWS WAF AWS Firewall
Manager
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Data protection
Build with comprehensive data protection in the cloud
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Data protection
Build with comprehensive data protection in the cloud
AWS Cloud
AWS KMS
key
Amazon CloudFront Amazon Simple Storage
Service (Amazon S3)
Amazon Macie
Virtual private cloud (VPC)
AWS Certificate
Manager (ACM) Availability Zone 1 Availability Zone 2
AWS KMS
Instances Auto Scaling group Instances key
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Compliance
Automate continuous compliance and auditing at scale
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Compliance, management and governance
Automate continuous compliance and auditing at scale
AWS Cloud
AWS Organizations
Security
checklist
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Call to action
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Call to action
• Learn more about AWS security: https://aws.amazon.com/security/
• Participate in Activation Days for hands-on workshops and best practices from SMEs:
https://awsactivationdays.splashthat.com/
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Visit the Migrate. Modernize. Build. resource hub
Dive deeper into these resources:
… and more!
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Training and Certification
Access 600+ free digital courses with AWS Skill Builder
Focus on the cloud skills and services that are most relevant to you across
30+ AWS solutions, including digital self-paced learning plans and ramp-up
guides
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Thank you for attending AWS Innovate – Migrate. Modernize. Build.
twitter.com/AWSCloud
facebook.com/AmazonWebServices
youtube.com/user/AmazonWebServices
linkedin.com/company/amazon-web-services
twitch.tv/aws
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Thank you!
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2024, Amazon Web Services, Inc. or its affiliates. All rights reserved.